Privacy Policy
Effective date: 7 August 2026This Privacy Policy describes how Diskus AI (“Diskus”, “we”, “us”) collects, uses, and protects information when you use our websites and applications, including Diskus AI Email, Bhagya Jyotish, Cricket Wise, Card Games, KarmaQ, Astra Home, and other products in the Diskus suite (together, the “Services”).
Greenbox Safe is covered by its own policy, not this one. It is an offline encrypted vault with no Diskus account, no sign-in and no server of ours behind it, so the account-based collection described below does not happen there and describing it here would misstate what the app does. See the Greenbox Safe Privacy Policy.
1. Information we collect
- Account information. When you create a Diskus account, we collect your name, email address, and authentication credentials. Passwords are stored only as salted cryptographic hashes.
- Sign-in with Google. If you choose to sign in with Google, we receive your basic profile information from Google: your name, email address, and profile picture. We do not receive your Google password.
- Application content. Content you create or connect within the Services (for example, mail accounts you connect in Diskus AI Email, charts you create in Bhagya Jyotish, or your career, saves and in-game balances in Cricket Wise and Card Games) is processed to provide the Service you requested.
- Technical data. We collect limited technical logs (IP address, device/browser type, timestamps, error diagnostics) needed to operate, secure, and debug the Services.
2. Google user data
Some Services connect to Google APIs with your explicit consent — for example, connecting a Gmail mailbox to Diskus AI Email. In those cases:
- We access only the data and scopes you approve on the Google consent screen.
- Mailbox data is used solely to provide the email features you requested — displaying, organising, searching, and sending your mail. We do not use Google user data for advertising, and we do not sell it to anyone.
- Access and refresh tokens are stored encrypted, and mailbox content is processed within the application; AI features operate on your data only to serve you, never to build advertising profiles.
- You can revoke our access at any time from your Google Account permissions page, and we will no longer be able to access the associated data.
Diskus AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Astra Home
Astra Home controls music and air conditioning in a home, and — where the house has the wiring and an always-on hub for it — lighting, curtains and televisions. It also carries a house intercom: messages, calls and file handovers between the phones, tablets and wall panels in that same home. Which of these you get depends on what is installed in your home, and the store listing sets out the difference. It is built local-first: the app talks to a hub on your own network, which may be a separate always-on machine or the app itself, and most of what it does stays on that network. That is how the app behaves today rather than a promise about every future feature. It does reach the internet in the places named below, and we will revise this section as the app changes.
- What stays on your device. Conversations, the record of calls that took place, and the people you have pinned as favourites are written on the device that took part, and are not currently copied to our servers. The app keeps roughly the most recent 500 messages per conversation and discards older ones. It does not currently back conversations up anywhere, so a device that is reset or reinstalled loses its own history.
- What the hub keeps. The hub is the software running on a machine in your home — often a small always-on box, sometimes the app itself on a desktop. For each device on the intercom it holds the nickname and location somebody gave it, the name the device reports for itself, the address it connected from, when it was last heard from, and, where notifications are switched on, a notification token for it. It remembers up to 50 devices and drops the longest-silent first. A message for a device that is not connected waits on the hub — at most 200 per device — and is removed as soon as it is handed over; that queue is held in memory and does not survive the hub restarting. A call is held for at most 45 seconds while a phone wakes. The hub keeps no message history and makes no recordings. Because the hub is a machine in your home, what it holds is under your household's control, not ours.
- What other devices in your home can see. Every device on the intercom is shown the others: the nickname and location set for them, the name each device reports, the address the hub saw it connect from, and the Diskus account signed in on it. Notification tokens are deliberately not part of that list.
- Calls. The hub carries only the invitation, the answer and the network details the two devices need to find each other. The audio and video itself goes directly between the two devices and is encrypted by WebRTC's own transport encryption. No relay servers are configured, so on an ordinary home network call audio and video do not currently pass through our servers or anyone else's.
- Camera and microphone. Said plainly, because it is worth being plain about: the microphone opens when you place or answer a call, and when you tap the microphone button to speak a command. The camera opens only for a video call — one you place as a video call, or one you answer where a picture is being offered — and you can turn it off during a call. A voice call does not open the camera. Neither is opened while the app is in the background, and nothing from either is recorded to a file by the app.
- Spoken commands. When you tap to speak, the words are turned into text by the speech recognition built into your device's platform; on most Android devices that means your speech is processed by Google under Google's own terms, and on those devices it needs an internet connection. What happens next — matching what you said to a room or a device and switching it — happens on the device and on your hub. We do not receive the audio or the transcript.
- Notifications. Notifications are currently offered on Android only, and only if you allow them. If you do, the device is issued a registration token by Google's Firebase Cloud Messaging and passes it to your hub, which stores it so it can wake the device for an incoming call or message. Your hub sends the notification to Firebase, which delivers it — so the notification's contents, currently the sender's name and either the message text or a note that a file was sent, pass through Google. If you decline, no token is issued and the rest of the app carries on working.
- Looking for devices on your network. When you ask the app to find a hub, or run the setup that builds your house, it listens for a hub announcing itself on your local network and looks for household equipment it knows how to control — such as Sonos, HEOS/Denon, LG televisions and CoolMasterNet air-conditioning gateways — by sending a standard discovery request and trying a small number of known ports on your own subnet. This is started by you, from a button, rather than run continuously in the background. What it finds is used to build your house on your hub; the app does not send an inventory of your network to us.
- Handing files to another device — please read this one. A file you share goes directly from the sending device to the receiving one over your local network, over plain HTTP, and is not encrypted. Anyone already on that network who obtained the link could fetch the file. Offers are held in memory, stop working the moment the sending app closes, are not uploaded anywhere and are not backed up — so there is no copy for us to hold, and none for us to delete. It is meant for handing a photo to somebody in the same house; we would not use it for anything confidential, and not at all on a network you do not trust.
- What reaches our servers. Signing in, as described above, and the list of homes your account belongs to — each home's name and timezone, your role and permissions in it, and the credential your device uses to prove itself to that home's hub, which the app stores in your device's platform keystore. A hub registered with Astra pulls its configuration and the access rules from us, so where a home is set up centrally, its room and device names and the local addresses of its equipment are held by us as well; a home set up from the app keeps that on the hub. The app does not send your device activity, conversations, calls or files to us, and it keeps working from what it already holds when we are unreachable.
- Traffic inside your home is not encrypted. The app speaks plain HTTP to the hub and to household equipment, because that equipment has no certificates. Connections that leave your home — to us and to Firebase — are HTTPS. Someone with access to your home network could observe local control traffic, and we would rather say so than imply otherwise.
Deleting your Diskus account removes your identity and your membership of any home, by the route described under “Data retention & deletion” below. Two things are not ours to erase for you, because we never held them: what your hub keeps, which lives on a machine in your home, and the conversations and call records on each device, which are cleared by removing the conversation in the app or by uninstalling it. If you would like help working out what to clear, write to hello@diskus.ai.
Astra Home is a household utility meant for the adults who set up and run a home; it is not directed to children, and the “Children” section below applies to it as it does to the rest of the Services.
4. How we use information
- To provide, maintain, and improve the Services.
- To authenticate you across Diskus applications through our single sign-on platform (Astra).
- To secure the Services, prevent abuse, and debug failures.
- To communicate with you about your account or material changes to the Services.
We do not sell personal information. We do not share personal information with third parties for their own marketing.
5. Data retention & deletion
You may request deletion at any time — from inside any Diskus app under Settings → Account → Delete account, or from diskus.ai/delete-account.html without signing in. Confirmed requests are erased after a 30-day grace period, during which you can cancel by signing in.
Two categories survive erasure, and we state them plainly rather than let you discover them later:
- Payment and transaction records are retained for 8 years from the end of the financial year in which each purchase was made. Tax and accounting law overrides the right to erasure (UK GDPR / EU GDPR Art. 17(3)(b) and (e)); Discus IT is registered and operated in India, and this is the period set by the Companies Act 2013.
- Where a payment exists, the application content attached to it is retained on the same basis, for the same period, and processed only for tax, refunds, chargebacks and disputes — never for analytics, product development or marketing.
Both are destroyed automatically when the period expires. You do not have to ask a second time.
Where you have never paid us, application content is deleted outright rather than merely stripped of your email address. Your identity record is removed in every case, so anything retained is no longer linked to your name or email. Backups expire within 35 days; technical logs containing IP and device identifiers expire after 90 days. Disconnecting a linked Google account deletes the associated tokens immediately. Full detail is on the Data Deletion page.
6. Data security
Services run on hardened cloud infrastructure with encryption in transit (TLS) and at rest. Internal access to production data is restricted, credentialed, and audited. Authentication across the suite uses asymmetric, signed tokens rather than shared secrets.
7. International transfers
Our infrastructure is primarily hosted in India (AWS Asia Pacific). Where data is processed in other regions, we apply the same safeguards described in this policy.
8. Cookies
This website sets no cookies; applications use only strictly necessary session credentials. See the full Cookie Policy.
9. Your rights
Depending on where you live, you have some or all of the following rights, and we honour them for all users regardless of location:
- Access & portability — receive a copy of the personal data we hold about you.
- Correction — have inaccurate personal data corrected.
- Erasure — have your account and data deleted (see Data Deletion).
- Withdrawal of consent — withdraw consent for processing that relies on it (for example, disconnecting a linked Google account).
- Grievance & complaint — raise a grievance with us, and escalate to your supervisory authority: the Data Protection Board of India under the Digital Personal Data Protection Act, 2023 (DPDP Act); your national authority under the GDPR (EU/EEA); or the California Attorney General under the CCPA/CPRA. We do not “sell” or “share” personal information as defined by the CCPA.
To exercise any right, email hello@diskus.ai. We respond within 30 days and may ask you to verify ownership of the account first.
10. Grievance redressal (India)
In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDP Act, 2023, grievances are handled by our Grievance Officer: reachable at hello@diskus.ai (subject line “Grievance”). Acknowledgement within 24 hours; resolution within 15 days.
11. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. Where the DPDP Act applies, we do not process the data of users under 18 without verifiable parental consent.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced within the Services or by email, and the effective date above will be revised.
13. Contact
Questions or requests regarding privacy: hello@diskus.ai.